USN-8879-1: dozens of flaws in the linux-oracle kernel on Ubuntu 20.04 LTS
Ubuntu fixes numerous vulnerabilities in the linux-oracle 5.15 kernel for Ubuntu 20.04 LTS. Reboot required, along with recompilation of third-party modules.
UptimeMag editorial team · 6 October 2026 · 1 min read

Canonical published advisory USN-8879-1 on 6 October 2026, fixing several vulnerabilities in the linux-oracle 5.15 kernel for Ubuntu 20.04 LTS (Focal Fossa). The affected package, linux-oracle-5.15, is the one used by Ubuntu instances optimised for Oracle Cloud Infrastructure. Anyone running Ubuntu 20.04 VMs on Oracle Cloud should plan the update and reboot.
What the advisory fixes
According to the official advisory, the flaws addressed include:
- CVE-2022-3114: the i.MX clock driver did not correctly handle certain memory allocation failures, resulting in a null pointer dereference. A local attacker could exploit this to cause a denial of service (system crash).
- CVE-2025-10263: on some Arm processors, broadcast TLB invalidation can complete before memory writes made via the invalidated translation have been globally observed. A local attacker could write to memory after permission had been revoked, bypassing memory protections or escalating privileges.
The advisory also lists a very large number of additional CVEs fixed in the kernel, touching practically every subsystem (networking, filesystems, USB drivers, Bluetooth, KVM, the scheduler and many others), without individual descriptions in the text published by Canonical.
Fixed version and update instructions
| Release | Package | Fixed version |
|---|---|---|
| 20.04 LTS (focal) | linux-image-5.15.0-1114-oracle | 5.15.0-1114.120~20.04.1 |
| 20.04 LTS (focal, Ubuntu Pro) | linux-image-oracle | 5.15.0.1114.120~20.04.1 |
| 20.04 LTS (focal, Ubuntu Pro) | linux-image-oracle-5.15 | 5.15.0.1114.120~20.04.1 |
Source: official Ubuntu advisory, USN-8879-1.
Note: the update involves an ABI change. After a standard upgrade, the system needs to be rebooted. Anyone with third-party kernel modules must recompile and reinstall them: this happens automatically with a standard upgrade, unless the kernel metapackages (e.g. linux-generic) have been manually uninstalled.
Canonical notes that Ubuntu Pro extends security coverage to ten years for more than 25,000 packages in Main and Universe, and is free for up to five machines.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.